CircleSpeak ← Back to app

CircleSpeak Privacy Policy

Effective: 31 July 2026

Scope and contact

This policy applies to the CircleSpeak website, Web app, iOS and Android apps, support messages, and service operations. CircleSpeak is operated by Buildmind AI, a Hong Kong company. “CircleSpeak”, “we”, and “us” mean Buildmind AI. Our business and postal address is Unit A16, Block C, 2/F, Wong King Industrial Building, 192-198 Choi Hung Road, San Po Kong, Hong Kong. Email [email protected] for privacy, access, correction, export, or deletion requests.

Information we handle

We handle account name and email, protected authentication records, verification and session details; AAC profile display name, age band, communication notes, language, voice, management and accessibility settings; Care Circle names, roles, invitations and membership; cards, spoken phrases, board layout, suggestions, conversations and messages; Care Circle alerts, delivery state, and Care Circle response acknowledgement; uploaded or generated card images; support correspondence; and technical security data such as timestamps, IP address, browser or device information, rate-limit signals, locally hashed error fingerprints, app version/platform, and privacy-safe audit events. Error messages and stack traces are not sent; fingerprints expire after 30 days.

How we collect information

We collect information directly when an account holder signs up, creates a profile, changes a board, uploads an image, contacts support, or makes a privacy request. We also receive information from other authorised Care Circle members when they send messages, suggest cards, or manage invitations, and collect limited technical and security information automatically when the website, app, or API is used.

How we use data

We use information to provide the AAC board and Care Circle, authenticate accounts, deliver email, protect the service, investigate problems, answer support and privacy requests, and improve service reliability. We do not sell personal information or serve targeted advertising. Public marketing pages use privacy-first Cloudflare Web Analytics to understand page views and performance; it is not loaded on signed-in app, invitation, or account-recovery pages.

Care Circle visibility

Active members can see the shared AAC profile, communication settings and notes, board, card images, suggestions, and other active members’ display names and roles. Members see conversations they belong to; guardians can manage membership and see all profile conversations. Guardians can see member contact addresses for circle management. Other roles see their own contact address, not other members’ email addresses.

Service providers and overseas processing

CircleSpeak uses Cloudflare for Web and API hosting, database and image storage, email delivery, security controls, and operational logs. These services may process information in countries where their systems operate. Optional AI requests are sent to a Volcengine service endpoint in China. We share only what is needed to provide and protect CircleSpeak, and may disclose information where law requires it or to address a serious safety or security issue.

Optional AI image generation

If a user chooses Generate with AI, CircleSpeak sends the card label, spoken phrase, category, character choice, and generation settings to the Seedream service through Volcengine, and may also send a CircleSpeak style or character reference image when reference guidance is enabled. This processing occurs in China and may otherwise involve processing outside Australia. A generated preview may load from a provider URL, so the provider may also receive network details such as the device IP address and browser information. Before the first request for an account and AAC profile on a device, CircleSpeak asks for explicit permission; that permission can be reset beside the AI controls. Do not include names, diagnoses, health details, locations, or other sensitive personal information. Review every generated image before use, and use the in-app Report action if a result is unsafe, inappropriate, misleading, or raises a privacy concern.

Storage and security

CircleSpeak uses encrypted network connections, account and role checks, rate limits, private custom-image access, and privacy-safe audit records. Native session credentials use the platform Keychain or Keystore and Android app backups are disabled. The app keeps a local IndexedDB cache in a separate area for each signed-in account. Signing out locks that account's cache; the in-app device-data action deletes only that account's cache and preferences. The server removes common EXIF, location, device, and text metadata from supported uploaded JPEG, PNG, and WebP card images before storage. No service can guarantee absolute security.

Retention and your choices

We keep account, AAC profile, card, image, Care Circle, and conversation information while the account or shared profile remains active. AI-generated image options that are not attached to a card or card suggestion are kept for up to seven days and then deleted automatically. Removing an image from a card only unlinks it from that card; it does not erase the generated option during this period. Care Circle alerts and response acknowledgements expire after 30 days. Profile settings can export the current local workspace. Request an account-linked export, access, or correction through [email protected]. Signed-in users can start permanent account deletion in Profile settings, which we aim to complete within 30 days after identity and shared-profile scope checks. Privacy-safe audit events are kept for 90 days. Resolved generated-content reports and completed or cancelled deletion-request evidence are kept for up to two years. Cloudflare Workers logs expire within seven days, and D1 point-in-time recovery history expires within 30 days on the paid production plan. Residual deleted data may remain inaccessible in that recovery history until expiry. After account deletion completes, CircleSpeak keeps a one-way hashed account reference for up to 30 days solely so an app or browser retaining the matching anonymous local reference can recognise completion and delete that account's local cache. This signal contains no email, name, or workspace content and is cleared after the signal period. A legal hold or unresolved dispute may require a documented exception.

Children and authorised adults

A child or teenager’s information must be managed by an adult parent, guardian, or authorised care or education professional with permission to provide it. Do not create a child profile, upload an image, or invite a member without the required authority and consideration for the child’s dignity and preferences.

Contact and complaints

Email [email protected] with “Privacy complaint” in the subject, what happened, and the outcome you want. Include the account email, but never send a password, OTP, session token, or invite link. We aim to acknowledge privacy requests within two business days, investigate, and provide a response, scope, or next steps within five business days. If you remain concerned, reply to request internal escalation. You may also contact the privacy regulator that applies to you, including the Office of the Australian Information Commissioner where applicable.

Back to appAccount deletion detailsSupportTerms